First published: Mon Dec 26 2022(Updated: )
The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wpswings Return Refund And Exchange For Woocommerce | <4.0.9 | |
<4.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4047 has a high severity rating due to the potential for remote code execution from unauthenticated users.
To fix CVE-2022-4047, update the Return Refund and Exchange for WooCommerce plugin to version 4.0.9 or later.
Users of the Return Refund and Exchange for WooCommerce plugin on WordPress versions prior to 4.0.9 are affected by CVE-2022-4047.
CVE-2022-4047 is a file upload vulnerability that can lead to remote code execution.
Yes, unauthenticated users can exploit CVE-2022-4047 to upload arbitrary files, potentially leading to remote code execution.